Executive brief
The Jenkins EC2 Fleet Plugin, which manages Amazon EC2 instances for build tasks, contains a security flaw where it fails to verify user permissions for certain actions. This allows an attacker with basic access to the Jenkins dashboard to trick the system into sending sensitive AWS credentials to a server they control. If exploited, this could lead to the theft of cloud infrastructure credentials, potentially allowing unauthorized access to the organization's Amazon Web Services environment.
Technical details
A missing permission check in Jenkins EC2 Fleet Plugin versions 4.2.3.539.v8fedff2a_81c3 and earlier allows an attacker with Overall/Read permission to exploit an unprotected HTTP endpoint. By providing an attacker-specified URL and a credential ID (obtained through separate means), the attacker can force the plugin to initiate a connection to that URL using the specified credentials. This results in the transmission and subsequent capture of sensitive AWS credentials stored within the Jenkins credential store. The vulnerability is categorized as a missing authorization check (CWE-862).
Affected products
- Jenkins Project EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier
Timeline
- 2026-06-24: disclosed: Initial advisory publication